drawio-aws
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the
drawio-ai-kitpackage from an external GitHub repository (github:sparklabx/drawio-ai-kit) using thenpm i -gcommand. - [DYNAMIC_EXECUTION]: The workflow involves scaffolding a JavaScript file (
build.mjs), modifying its contents based on user requirements, and executing it vianode build.mjs. This represents runtime assembly and execution of code. - [COMMAND_EXECUTION]: The skill makes extensive use of a custom CLI tool (
drawio-ai) to perform searches, validate diagrams, and render output. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied architecture descriptions which are then interpolated directly into a subagent prompt. This data eventually influences the generation of executable code. 1. Ingestion points: User request and clarifications in
SKILL.md. 2. Boundary markers: None present; the user input is passed verbatim into the subagent prompt. 3. Capability inventory: Shell command execution (drawio-ai), Node.js script execution (node), and network access (via package installation). 4. Sanitization: No explicit sanitization or validation of the user-provided request is described.
Audit Metadata